Framework overlap

Does SOC 2 cover ISO 15189:2022?

You hold SOC 2 and have been told to do ISO 15189:2022. Here is how much overlaps, control by control.

23% of ISO 15189:2022 you already have

SOC 2 already covers about 23% of ISO 15189:2022, leaving 57 of 74 controls as genuinely new work.

Already covered 6 Likely covered 11 New work 57

What is genuinely new work

Nothing in SOC 2 reaches these. This is the list to scope.

27006-6.1
Competence of personnel
27006-6.2
Personnel Records
5.4
Establishing Audit Programme
6.8
Externally Provided Products and Services
7.5
Threat assessment
7.7
Likelihood estimation
7.8
Consequence estimation
8.5
Control effectiveness review
8.8
Management of technical vulnerabilities
8.9
Management Reviews
ISO-15189-4.1
Impartiality
ISO-15189-4.2
Confidentiality
ISO-15189-4.3
Requirements regarding patients
ISO-15189-5.2
Laboratory director
ISO-15189-5.3
Laboratory activities
ISO-15189-5.5
Objectives and policies
ISO-15189-6.3
Facilities and environmental conditions
ISO-15189-6.4
Equipment
ISO-15189-6.5
Equipment calibration and metrological traceability
ISO-15189-6.6
Reagents and consumables
ISO-15189-7.2
Pre-examination processes
ISO-15189-7.3
Examination processes
ISO-15189-7.5
Nonconforming work
ISO-15189-7.6
Data and information management
ISO-15189-7.7
Complaints
ISO-15189-8.2
Management system documentation
ISO-15189-8.3
Control of documents
ISO-15189-8.5
Actions addressing risks and opportunities
ISO-15189-8.6
Improvement
ISO-15189-8.7
Nonconformities and corrective actions
ISO-15189-8.8
Evaluations
ISO-15189-8.9
Management reviews
ISO-17025-4.1
Impartiality
ISO-17025-4.2
Confidentiality
ISO-17025-6.2
Personnel
ISO-17025-6.3
Facilities and environmental conditions
ISO-17025-6.4
Equipment
ISO-17025-6.5
Metrological traceability
ISO-17025-6.6
Externally provided products and services
ISO-17025-7.1
Review of requests, tenders and contracts
ISO-17025-7.10
Nonconforming work
ISO-17025-7.11
Control of data and information management
ISO-17025-7.2
Selection, verification and validation of methods
ISO-17025-7.3
Sampling
ISO-17025-7.4
Handling of test or calibration items
ISO-17025-7.5
Technical records
ISO-17025-7.6
Evaluation of measurement uncertainty
ISO-17025-7.7
Ensuring the validity of results
ISO-17025-7.8
Reporting of results
ISO-17025-7.9
Complaints
ISO-17025-8.2
Management system documentation
ISO-17025-8.3
Control of management system documents
ISO-17025-8.4
Control of records
ISO-17025-8.5
Actions to address risks and opportunities
ISO-17025-8.6
Improvement
ISO-17025-8.8
Internal audits
ISO-17025-8.9
Management reviews
Show the 17 you already have
6.5
Preparing and Distributing Audit Report
6.7
Conducting Audit Follow-up
ISO-15189-5.1
Legal entity
ISO-15189-5.4
Structure and authority
ISO-15189-6.2
Personnel
ISO-15189-6.7
Service agreements
6.4
Logging and Monitoring
6.6
Confidentiality or non-disclosure agreements
A.1
Point-of-Care Testing Additional Requirements
ISO-15189-5.6
Risk management
ISO-15189-6.8
Externally provided products and services
ISO-15189-7.4
Post-examination processes
ISO-15189-7.8
Continuity and emergency preparedness
ISO-15189-8.1
General requirements
ISO-15189-8.4
Control of records
ISO-17025-8.1
Options
ISO-17025-8.7
Corrective actions

How this is calculated

Already covered means a mapping runs from a control in SOC 2 to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition